1,567 questions with Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

An Azure Server is Being Abused

How can I report an Azure instance that is being used to send spam mail? I am willing to send full .eml files of the spam emails with their full headers. The IP address is: 20.49.19.146 The emails are being sent from: ******@wlmrt.com

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-09-12T23:02:18.887+00:00
Tobias 21 Reputation points
accepted 2020-09-13T15:53:31.707+00:00
Tobias 21 Reputation points
1 answer One of the answers was accepted by the question author.

vulnerability assessment solution... downtime?

Deploy an extension to your virtual machines to enable a vulnerability assessment solution If I enable this solution to our VMs Will there be a downtime on my VMs? Or do I have to consider anything for my VMs?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-09-10T07:39:42.077+00:00
Jim 46 Reputation points
accepted 2020-09-10T11:18:53.707+00:00
Jim 46 Reputation points
1 answer One of the answers was accepted by the question author.

Protect Gen V1 VM running ubuntu 18.04. threats from Drovorub.

have a Gen V1 VM running ubuntu 18.04. There is a request to enable UEFI boot to remediate threats from Drovorub. Is there a process of best practices to protect Azure VM on Linux from Drovorub?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,101 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-30T08:20:08.95+00:00
sachin Chand 21 Reputation points
accepted 2020-09-07T20:55:16.66+00:00
sachin Chand 21 Reputation points
2 answers

Security Rules getting deleted automatically

While creating and adding new security rules , security rules are getting deleted automatically after sometime. Can you help me out with this?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-28T13:58:45.963+00:00
Suyal, Ashish 1 Reputation point
commented 2020-09-02T14:45:56.743+00:00
Saurabh Sharma 23,851 Reputation points Microsoft Employee Moderator
1 answer

Vulnerability Scan Timeout

I have a recommendation in the Azure Security Advisor "VA2065 - Server-level firewall rules should be tracked and maintained at a strict minimum" on a number of sql server instances. My understanding of how to remediate these is: Adjust…

Azure SQL Database
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-10T05:10:27.98+00:00
Jim Pelletier 1 Reputation point
commented 2020-08-31T20:41:11.267+00:00
James Hamil 27,226 Reputation points Microsoft Employee Moderator
1 answer

Microsoft Defender ATP for Linux - Attack Surface Reduction

Are there plans to incorporate ASR rules for the MS Defender ATP for Linux agent in the near future? This feature appears to be the only host intrusion component within the Defender ATP agent and as of now, it is only available for Windows VMs. …

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-10T18:20:07.29+00:00
Borgna, Andrew 1 Reputation point
commented 2020-08-31T20:29:39.993+00:00
James Hamil 27,226 Reputation points Microsoft Employee Moderator
1 answer

Attacked from AZURE?

Hi, probably this is the wrong section, I apologize for that. I recently received a message from my NAS located in my house (ITALY) saying that the IP address 40.87.2.69 tried to connect 10 times to SSH service, today 12/08/20 at 10:23(CEST) and it was…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-12T10:56:39.383+00:00
FlashNoob98 1 Reputation point
commented 2020-08-31T19:14:22.867+00:00
James Hamil 27,226 Reputation points Microsoft Employee Moderator
1 answer

Can Azure CDN protect against known vulnerabilities?

We have a website https://ourwebsite.web.core.windows.net/ which needs to be made public(available on Internet for anyone) and did a Qualys scan using an external scanner on it which found 40 vulnerabilities. The website has static HTML, CSS is inside…

Azure Content Delivery Network
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-13T01:51:36.797+00:00
Steve 66 Reputation points
commented 2020-08-31T19:08:11.917+00:00
James Hamil 27,226 Reputation points Microsoft Employee Moderator
1 answer

what is gurantee in Azure SLA : uptime or feature availability ?

what is guarantee in Azure SLA : uptime or feature availability ?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-27T08:00:04.467+00:00
Mohit Kumar 11 Reputation points
commented 2020-08-27T23:24:27.457+00:00
bharathn-msft 5,106 Reputation points Microsoft Employee Moderator
1 answer

How to Create DLP Policies

Within Azure, where do I create Data Loss Prevention Polices? When I select the Security Center and the Policy and Compliance center it show "No active subscriptions." Am I looking in the correct section? The setup is vastly different from O365…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-26T13:19:40.63+00:00
Chamberlain, Briana 1 Reputation point
answered 2020-08-26T16:45:04.907+00:00
T. Kujala 8,766 Reputation points
1 answer

Defender ATP for Linux Intelligence Updates

Do MS Defender for Linux agents require external access for intelligence updates? Or can a share repository be set up similar to the instruction below for Windows that would allow us to have a centralized VM for pulling down and distributing updates to…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-11T12:32:23.74+00:00
Borgna, Andrew 1 Reputation point
commented 2020-08-21T16:14:08.933+00:00
Borgna, Andrew 1 Reputation point
1 answer

Unable to receive Alert emails for more than 2 recipient using Azure security center

Last Friday, we were able to received the alerts for 2 recipient, and if we increase the recipient list then the alert generated on the portal but unable to received an E-mail. Is this is the limitation of the security center. Today, we are not getting…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-17T07:04:08.053+00:00
vijay saini 1 Reputation point
answered 2020-08-17T10:36:54.247+00:00
VipulSparsh-MSFT 16,316 Reputation points Microsoft Employee Moderator
1 answer One of the answers was accepted by the question author.

Can you get all settings programmatically?

Hello, I want to be able to quickly do a security audit of an Azure Active Directory and O365 environment. So I wonder if you can get all settings in Azure Active Directory, Office365, Exchange Online and Teams programmatically? Just a long list of the…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-08-10T07:57:23.947+00:00
JohnITHelpNeeded 21 Reputation points
accepted 2020-08-13T13:54:03.387+00:00
JohnITHelpNeeded 21 Reputation points
2 answers One of the answers was accepted by the question author.

Cannot bulk load because the file 'container' + file' could not be opened. Operating system error code (null).

I am not sure what is going on with this quation body it keeps nagging that there need to be at least 10 characters inside this body..... Loading a file from the Azure Blob storage should be relatively easy when you are working with a Azure SQL…

Azure SQL Database
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
790 questions
Azure Migrate
Azure Migrate
A central hub of Azure cloud migration services and tools to discover, assess, and migrate workloads to the cloud.
934 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-07-14T08:00:31.357+00:00
Jacobus Wooning 41 Reputation points
commented 2020-08-13T00:49:27.957+00:00
Mike Ubezzi 2,776 Reputation points
1 answer

Convert RecordType from ID number to associated value

I am querying audit logs from the security and compliance center, and want to use the field RecordType in my console app, but the number value is not help. Is there a way I can convert the ID value to an associated word value that has meaning?

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
2,465 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Entra | Microsoft Entra ID
asked 2020-08-05T18:55:57.317+00:00
Eisenhaur, Liam 21 Reputation points
commented 2020-08-06T19:08:24.017+00:00
Alfredo Revilla - Upwork Top Talent | IAM SWE SWA 27,526 Reputation points Moderator
2 answers

Compliance assessment and setting policies

Setting Security Center to Standard Plan allows for view and alteration of ASC policies. For assessment the framework can be chosen (e.g. ISO) However: looking at the assessment e.g. ISO I notice Windows level CCE policies Where do…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-07-15T15:00:58.087+00:00
Paul Schoorl 1 Reputation point
answered 2020-08-03T19:53:39.183+00:00
chakri 1 Reputation point
2 answers

Microsoft Defender ATP for Linux

My organization is currently testing Defender ATP for Linux in our Azure Dev Lab and I have a question about virus defintion(.dat) updates for the agents. The documentation that I've been able to find does not discuss the update files and I was wondering…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-07-31T18:04:23.163+00:00
Borgna, Andrew 1 Reputation point
answered 2020-08-03T18:52:18.007+00:00
Borgna, Andrew 1 Reputation point
1 answer One of the answers was accepted by the question author.

Enable AUdit Logging in the Security and Compliance Center

I am trying to figure out how to enable audit logging in the security and compliance center. I have only seen resources online talking about turning on the audit log search capabilities but not how to turn the audit logs in general for a company just…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Entra | Microsoft Entra ID
asked 2020-08-03T15:14:04.89+00:00
Eisenhaur, Liam 21 Reputation points
accepted 2020-08-03T16:01:09.84+00:00
Eisenhaur, Liam 21 Reputation points
2 answers

Turning off Azure Security Centre to cut monthly operations cost

How much does it cost for the Azure Security Centre access per month? My security team has already deployed IBM Q-Radar SIEM and wanted to cut the cost of operating Azure cloud, hence I wonder: How much does it cost monthly to run Azure Security…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Sentinel
asked 2020-07-22T07:41:07.79+00:00
EnterpriseArchitect 6,061 Reputation points
commented 2020-08-01T10:27:48.307+00:00
Ken Golitin 21 Reputation points
1 answer

Azure security centre

Hi, I need to enable the following policies in azure security centre. MFA vulnerability assessment Web application should be accessable over https These are all cost free or need to buy any licence? Kindly advise Thank you

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-07-25T01:57:59.357+00:00
Soundarya A 21 Reputation points
commented 2020-07-30T20:53:07.207+00:00
JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator